×êÑÐÈËÔ±ÑÝʾÈôºÎÀûÓÃChromeÀ©´ó·¨Ê½ÇÔÈ¡Ã÷ÎÄÃÜÂë
°ä²¼¹¦·ò 2023-09-041¡¢×êÑÐÈËÔ±ÑÝʾÈôºÎÀûÓÃChromeÀ©´ó·¨Ê½ÇÔÈ¡Ã÷ÎÄÃÜÂë
¾ÝýÌå9ÔÂ2ÈÕ±¨Â·£¬Íþ˹¿µÐÇ´óѧÂóµÏÑ··ÖУµÄÒ»×é×êÑÐÈËÔ±·¢ÏÖÄܹ»Í¨¹ýChromeÀ©´ó´ÓÍøÕ¾Ô´´úÂëÖÐÇÔÈ¡´¿Îı¾ÃÜÂë¡£¸ÃÎÊÌâÉæ¼°ä¯ÀÀÆ÷À©´ó¿É²»ÊÜÏ޶ȵؽӼûÆä¼ÓÔØµÄÍøÕ¾µÄDOMÊ÷£¬´Ó¶ø½Ó¼ûÓû§ÊäÈë×ֶεÈDZÔÚÃô¸ÐÔªËØ¡£¼øÓÚÀ©´ó·¨Ê½ºÍÍøÕ¾ÔªËØÖ®¼äûÓÐÈκΰ²È«Ììǵ£¬Òò¶øÀ©´óÄܹ»½Ó¼ûÔ´´úÂëÖпɼûµÄÊý¾Ý£¬²¢ÌáÈ¡ÆäËÁÒâÄÚÈÝ¡£´Ë±í£¬¸ÃÀ©´ó·¨Ê½¿ÉÄÜ»áÀûÓÃDOM APIÔÚÓû§ÊäÈëʱֱ½ÓÌáÈ¡ÊäÈëÖµ¡£Google°µÊ¾ËûÃÇÔÚµ÷²é´ËÊ¡£
https://www.bleepingcomputer.com/news/security/chrome-extensions-can-steal-plaintext-passwords-from-websites/
2¡¢Ï¤Äá´óѧµÚÈý·½·þÎñÌṩÉÌÔâµ½¹¥»÷²¿ÃÅÊý¾Ýй¶
¾Ý9ÔÂ3ÈÕ±¨Â·£¬Ï¤Äá´óѧ(USYD)й©£¬ÆäµÚÈý·½·þÎñÌṩÉÌÔâµ½¹¥»÷£¬µ¼Ö½üÆÚÉêÇëºÍ×¢²áµÄ¹ú¼ÊÉêÇëÈ˵ÄÐÅϢй¶¡£USYD³Æ¸ÃÎÊÌâ½öÏÞÓÚµ¥Ò»Æ½Ì¨£¬¶Ô´óѧµÄÆäËüϵͳûÓÐÓ°Ï죬³õ´ëÊ©²éҲûÓз¢ÏÖÈκα¾µØÑ§Éú¡¢½ÌÈËÔ±¹¤»òУÓѵÄÐÅϢй¶¡£¹«¿ªµÄÊÂÎñÐÅÏ¢²¢Î´×¢Ã÷й¶²úÉúµÄ¹¦·ò»òÄÄЩµÚÈý·½·þÎñÔâµ½¹¥»÷£¬Ä¿Ç°Ò²Ã»ÓйØÓÚUSYDϵͳÖжϵIJ¼¸æ¡£
https://www.bleepingcomputer.com/news/security/university-of-sydney-data-breach-impacts-recent-applicants/
3¡¢EclecticIQ°ä²¼ÀÕË÷Èí¼þKey GroupµÄÃâ·Ñ½âÃÜ·¨Ê½
ýÌå9ÔÂ1Èճƣ¬EclecticIQ°ä²¼ÀÕË÷Èí¼þKey Group£¨±ðÃûkeygroup777£©µÄÃâ·Ñ½âÃÜ·¨Ê½£¬ºÏÓÃÓÚ8Ô³õ¹¹½¨µÄ¶ñÒâÈí¼þ°æ±¾¡£Key GroupÖÁÉÙ×Ô½ñÄê1ÔÂÆð¾ÍÒ»Ïò»îÔ¾£¬¹¥»÷ÕßÐû³ÆËûÃǵĶñÒâÈí¼þʹÓõÄÊÇ"¾üÓü¶±ðAES¼ÓÃÜ"£¬µ«¸ÃlockerÔÚËùÓмÓÃܹý³ÌÖж¼Ê¹ÓÃÁ˾²Ì¬salt£¬Òò¶ø¸Ã¹æ»®ÓµÓп϶¨µÄ¿ÉÔ¤²âÐÔ£¬¼ÓÃÜÒ²ÓпÉÄܱ»Äæ×ª¡£¸Ã¹¤¾ßÈÔ´¦ÓÚÑéÖ¤½×¶Î£¬¿ÉÄܲ»ºÏÓÃÓÚÿ¸öKey GroupÑù±¾¡£
https://securityaffairs.com/150207/malware/key-group-ransomware-decryptor.html
4¡¢Callaway¹«Ë¾¹«¿ªÉæ¼°³¬¹ý110ÍòÓû§µÄÊý¾Ýй¶ÊÂÎñ
9ÔÂ1ÈÕ±¨Â·³Æ£¬ÃÀ¹ú¸ß¶û·òÇòÉ豸Ôì×÷É̺ÍÏúÊÛÉÌCallaway¹«¿ªÁ˽üÆÚ²úÉúµÄÊý¾Ýй¶ÊÂÎñ¡£CallawayÔÚ8ÔÂ29Èհ䲼֪ͨ£¬³Æ8ÔÂ1ÈÕ²úÉúµÄITϵͳÊÂÎñÓ°ÏìÁËÆäµçÉÌ·þÎñµÄ¿ÉÓÃÐÔ£¬²¢½«²¿Ãſͻ§ÐÅϢй¶¸øÎ´¾ÊÚȨµÄµÚÈý·½¡£¸ÃÊÂÎñÓ°ÏìÁËCallaway¼°Æä×ÓÆ·ÅÆOdyssey¡¢OgioºÍCallaway Gold PreownedÍøÕ¾µÄ¿Í»§£¬Ð¹Â¶ÐÅÏ¢Ô̺¬ÐÕÃû¡¢µØÖ·¡¢¶©µ¥º¹Çà¼Í¼¡¢°²È«ÎÊÌâºÍÕË»§ÃÜÂëµÈ£¬Éæ¼°ÁË1114954ÈË¡£ÓÉÓÚÃÜÂëºÍ°²È«ÎÊÌâµÈÕÊ»§ÐÅϢй¶£¬CallawayÒÑÇ¿ÔìËùÓпͻ§³ÁÖÃÃÜÂë¡£
https://therecord.media/topgolf-callaway-says-one-million-affected-by-breach
5¡¢SecuronixÅû¶ͨ¹ýMS SQL·Ö·¢FreeWorldµÄ¹¥»÷»î¶¯
SecuronixÔÚ9ÔÂ1ÈÕÅû¶ÁËͨ¹ýMS SQL·Ö·¢ÀÕË÷Èí¼þFreeWorldµÄ¹¥»÷»î¶¯DB#JAMMER¡£Æä¹¤¾ßÔ̺¬Ã¶¾Ù¹¤¾ß¡¢RAT payload¡¢·ì϶ÀûÓÃºÍÆ¾Ö¤ÇÔÈ¡¹¤¾ßÒÔ¼°ÀÕË÷Èí¼þ¡£FreeWorldËÆºõÊÇÀÕË÷Èí¼þMimicµÄбäÖÖ¡£³õʼ½Ó¼ûÊÇͨ¹ý±©Á¦ÆÆ½âMS SQL·þÎñÆ÷À´ÊµÏֵģ¬ÏÂÒ»½×¶Î±ØÒª²ÉÈ¡´ëÊ©¹¥»÷ϵͳ·À»ðǽ£¬ÏνÓÔ¶³ÌSMB¹²ÏíÀ´³ÉÁ¢ÓƾÃÐÔ£¬ÒÔ±ãÔÚϵͳ֮¼ä´«ÊäÎļþ£¬²¢×°ÖÃCobalt StrikeµÈ¹¤¾ß¡£¶øºó×°ÖÃAnyDesk£¬ºáÏòÒÆ¶¯£¬×îÖÕ×°ÖÃFreeWorld¡£
https://www.securonix.com/blog/securonix-threat-labs-security-advisory-threat-actors-target-mssql-servers-in-dbjammer-to-deliver-freeworld-ransomware/
6¡¢Cisco°ä²¼¹ØÓÚ¿ªÔ´ÇÔÈ¡·¨Ê½SapphireStealerµÄ»ã±¨
8ÔÂ31ÈÕ£¬Cisco°ä²¼Á˹ØÓÚ¿ªÔ´ÇÔÈ¡·¨Ê½SapphireStealerµÄ·ÖÎö»ã±¨¡£×Ô2022Äê12Ô³õ´Î°ä²¼ÒÔÀ´£¬SapphireStealerÔÚ¹«¹²¶ñÒâÈí¼þ´æ´¢¿âÖгöÏֵįµÂʲ»ÐÝÔö³¤¡£ËüÓµÓÐÍøÂçÖ÷»úÐÅÏ¢¡¢ä¯ÀÀÆ÷Êý¾Ý¡¢ÎļþºÍÆÁÄ»½ØÍ¼µÄÖ°ÄÜ£¬²¢¿Éͨ¹ýµ¥Ò»Óʼþ´«ÊäºÍ̸(SMTP)ÒÔZIPÎļþµÄ´ó¾Ö´«ÊäÊý¾Ý¡£´Ë±í£¬×êÑÐÈËÔ±»¹·¢ÏÖÁËSapphireStealerµÄ¶à¸ö±äÌ壬³ÆºÚ¿Í¸Ä½øÁËÔʼ´úÂë¿â£¬Ê¹ÆäÖ§³Ö¸ü¶àµÄÊý¾Ýй¶»úÔ죬Òò¶ø²úÉúÁ˶à¸ö±äÌå¡£
https://blog.talosintelligence.com/sapphirestealer-goes-open-source/


¾©¹«Íø°²±¸11010802024551ºÅ